| ▲ | some_furry 16 hours ago | ||||||||||||||||||||||||||||||||||||||||
Why is a keyring important to you? Would "fetch a short-lived age public key" serve your use case? If so, then an age plugin that build atop the AuxData feature in my Fediverse Public Key Directory spec might be a solution. https://github.com/fedi-e2ee/public-key-directory-specificat... But either way, you shouldn't have long-lived public keys used for confidentiality. It's a bad design to do that. | |||||||||||||||||||||||||||||||||||||||||
| ▲ | deknos 4 hours ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||
We need a keyring at a company. Because there's no other media for communicating, where you reach management and technical people in companies as well. And we have massive issues due to the fact that the ongoing-decrying of "shut everything off" and the following non-improvement-without-an-alternative because we have to talk with people of other organizations (and every organization runs their own mailserver) and the only really common way of communication is Mail. And when everyone has a GPG Key, you get.. what? an keyring. You could say, we do not need gpg, because we control the mailserver, but what if a mailserver is compromised and the mails are still in mailboxes? the public keys are not that public, only known to the contenders, still, it's an issue and we have a keyring | |||||||||||||||||||||||||||||||||||||||||
| ▲ | johnisgood 16 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||
> you shouldn't have long-lived public keys used for confidentiality. This statement is generic and misleading. Using long-lived keys for confidentiality is bad in real-time messaging, but for non-ephemeral use cases (file encryption, backups, archives) it is completely fine AND desired. > Would "fetch a short-lived age public key" serve your use case? Sadly no. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||